OBL-01Obligations and Compliance
Obligation inventory
Legal, regulatory and contractual obligations that apply are identified, owned and kept current.
Why it exists
You cannot meet an obligation you have not written down.
What usually proves it
Obligation register with source, owner and evidence link.
Smaller organizations
One register, reviewed when a contract or law changes.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC2.3
- Fully addressedISO/IEC 27001 Annex A · A.5.31
- Fully addressedNIST Cybersecurity Framework · GV.OC-03
- Partially addressedPCI DSS · 12.1 — Scoped to PCI DSS obligations.
- Partially addressedHIPAA Security Rule · 164.316 — Documentation duty rather than an inventory.
- Partially addressedGDPR · Art. 30 — Records of processing rather than obligations.
- Partially addressedEU AI Act · Art. 16 — Provider obligations are enumerated by the Act itself.
- Fully addressedNIST AI Risk Management Framework · GOVERN 1.1